Protecting Classifiers From Attacks. A Bayesian Approach

📅 2020-04-18
🏛️ arXiv.org
📈 Citations: 2
✨ Influential: 0
📄 PDF
🤖 AI Summary
To address the vulnerability of classifiers to feature-manipulation attacks—such as those in security-critical applications like malware detection and fraud identification—this paper proposes a Bayesian adversarial robustness framework that dispenses with the common-knowledge assumption. Methodologically, it introduces adversarial risk analysis into classifier defense for the first time, establishing a Bayesian modeling paradigm that requires no prior knowledge of attacker behavior. It further designs an inverse sampling scheme based on Approximate Bayesian Computation (ABC) and integrates attack simulation into the training phase, enabling scalable robust learning. The approach is compatible with large-scale differentiable models and preserves high classification accuracy while significantly improving robustness against both white-box and black-box attacks. Experimental results demonstrate superior defensive performance over mainstream adversarial training baselines.
📝 Abstract
Classification problems in security settings are usually modeled as confrontations in which an adversary tries to fool a classifier manipulating the covariates of instances to obtain a benefit. Most approaches to such problems have focused on game-theoretic ideas with strong underlying common knowledge assumptions, which are not realistic in the security realm. We provide an alternative Bayesian framework that accounts for the lack of precise knowledge about the attacker's behavior using adversarial risk analysis. A key ingredient required by our framework is the ability to sample from the distribution of originating instances given the possibly attacked observed one. We propose a sampling procedure based on approximate Bayesian computation, in which we simulate the attacker's problem taking into account our uncertainty about his elements. For large scale problems, we propose an alternative, scalable approach that could be used when dealing with differentiable classifiers. Within it, we move the computational load to the training phase, simulating attacks from an adversary, adapting the framework to obtain a classifier robustified against attacks.
Problem

Research questions and friction points this paper is trying to address.

Protecting classifiers from adversarial attacks in various domains
Addressing uncertainty about attacker behavior using Bayesian methods
Robustifying classification algorithms against malicious perturbations
Innovation

Methods, ideas, or system contributions that make the work stand out.

Bayesian decision theoretic framework
sampling from adversarial instance distributions
scalable robust classification training
🔎 Similar Papers
No similar papers found.
Komorebi AI Technologies | CUNEF Universidad | Institute of Mathematical Sciences | CNR-IMATI
V
Víctor Gallego
Komorebi AI Technologies
Roi Naveiro
Roi Naveiro
CUNEF Universidad
Probabilistic Machine LearningAdversarial Machine LearningBayesian StatisticsDecision Analysis
A
Alberto Redondo
Institute of Mathematical Sciences (ICMAT-CSIC)
D
David Ríos Insua
Institute of Mathematical Sciences (ICMAT-CSIC)
F
Fabrizio Ruggeri
CNR-IMATI